About the Role
Looking for an experienced Vulnerability Management & Penetration Testing Lead to support our client, in Singapore. The successful candidate will be responsible for developing, managing, and continuously improving the organization’s Vulnerability Management and Penetration Testing (VMPT) program in a regulated financial-services environment. This is a senior role combining vulnerability management, penetration testing, security governance, risk-based prioritization, remediation management, stakeholder engagement, and program leadership.
Key Responsibilities
- Vulnerability Management & Governance Build, operate, and continuously improve the organization’s Vulnerability Management and Penetration Testing (VMPT) program.
- Own the end-to-end vulnerability management lifecycle from discovery and triage through remediation, verification, and closure.
- Develop and maintain vulnerability management policies, standards, processes, procedures, and reporting.
- Lead vulnerability triage by assessing threat exposure, compensating controls, business impact, and overall risk.
- Prioritize remediation based on risk and drive accountability for remediation SLAs.
- Chair vulnerability and penetration testing governance forums and expedite overdue or high-risk findings to management.
- Track vulnerabilities, exceptions, residual risks, remediation status, and closure.
- Develop meaningful metrics, dashboards, and management reports covering vulnerability and penetration testing posture.
- Identify process gaps and drive continuous improvement from a Risk‑Based Vulnerability Management (RBVM) perspective.
- Research and recommend appropriate vulnerability management, penetration testing, security monitoring, and CSPM tooling.
- Work closely with cybersecurity, infrastructure, application, cloud, IT risk, and business stakeholders.
- Manage relationships with external security assessment and penetration testing vendors.
- Mentor and guide junior VMPT/security team members.
- Penetration Testing Own and manage the end-to-end penetration testing program, including scoping, rules of engagement, execution oversight, findings management, retesting, and closure.
- Develop and maintain an annual risk-based penetration testing plan.
- Coordinate penetration testing across: External and internal networks, Web applications, Mobile applications, APIs, Cloud environments, Wireless environments, Social engineering, Red team / Purple team exercises.
- Define and maintain penetration testing methodologies, standards, and Rules of Engagement.
- Apply recognized security testing frameworks and methodologies such as OWASP, PTES, NIST SP 800‑115, and MITRE ATT&CK.
- Review and validate penetration testing findings and remediation evidence.
- Conduct or oversee retesting to confirm effective remediation.
- Track exceptions and residual risks through appropriate acceptance or resolution.
- Manage external penetration testing vendors and ensure quality, coverage, and independence of testing.
- Support penetration testing requirements applicable to regulated financial institutions, including MAS Technology Risk Management (MAS TRM) requirements.
- Security Engineering & Monitoring Support security review and monitoring of production environments across hybrid infrastructure.
- Apply hands‑on knowledge of vulnerability management, penetration testing, and security engineering.
- Work with logging, monitoring, and SIEM platforms, including log configuration, formats, and log ingestion.
- Support security baseline governance and compliance using appropriate security tooling.
- Identify opportunities for process automation and workflow improvement using ITSM tools.
Requirements
- Minimum 7 years of relevant cybersecurity / information security experience.
- Strong experience in information security and/or IT risk management.
- Proven experience owning or leading a Vulnerability Management and/or Penetration Testing program.
- Experience establishing security processes, standards, governance, and reporting.
- Demonstrated leadership and stakeholder management skills, with the ability to drive initiatives across multiple departments.
- Strong understanding of cybersecurity risk and the ability to assess risks associated with business processes, technology, applications, infrastructure, and security programs.
- Experience communicating complex technical security matters to both technical and non‑technical stakeholders.
- Experience in process optimization and continuous improvement.
- Experience with process automation and ITSM workflows.
- Hands‑on experience in vulnerability management, penetration testing, and security engineering.
- Experience with industry‑recognized vulnerability management, penetration testing, and CSPM solutions.
- Experience working with external penetration testing/security assessment vendors is highly desirable.
- Experience in a regulated financial services environment is preferred.
- Strong knowledge of Risk‑Based Vulnerability Management (RBVM).
- Strong vulnerability triage and risk assessment capabilities.
- Ability to assess vulnerabilities based on actual threat exposure, compensating controls, business impact, and overall risk.
- Experience managing remediation SLAs, exceptions, residual risk, and closure.
- Knowledge of security logging and SIEM integration.
- Strong hands‑on penetration testing experience across multiple domains, including: Network, Web applications, Mobile applications, APIs, Cloud.
- Strong understanding of penetration testing methodologies and frameworks: OWASP Testing Guide, PTES, NIST SP 800‑115, MITRE ATT&CK.
- Familiarity with offensive security tools such as: Burp Suite, Nmap, Metasploit, Kali Linux, Cobalt Strike.
- Working knowledge of one or more scripting/programming languages such as Python, PowerShell, Java, Ruby, Node.js, Go, or C++.
Education & Certifications
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred.
Professional Certifications
One or more of the following is preferred: CISSP, CISM, CISA, SANS/GIAC certifications. Penetration testing/security testing certifications such as: OSCP, GPEN, GWAPT, CREST CRT/CCT, CEH.
Candidates who do not currently hold a penetration testing certification but have strong relevant experience and are willing to obtain an appropriate certification within one year may also be considered.
Key Skills
Vulnerability Management | Risk-Based Vulnerability Management | Penetration Testing | Security Testing | Cybersecurity | Information Security | Security Governance | Vulnerability Assessment | Remediation Management | Risk Assessment | Network Security | Web Application Security | Mobile Security | API Security | Cloud Security | CSPM | Red Team | Purple Team | OWASP | PTES | NIST SP 800‑115 | MITRE ATT&CK | Burp Suite | Nmap | Metasploit | Kali Linux | Cobalt Strike | SIEM | ITSM | Security Risk | MAS TRM
Pay
Pay: $6,000.00 - $30,000.00 per month
Benefits
- Additional leave
- Flexible schedule
- Health insurance
- Parental leave
- Professional development
- Promotion to permanent employee
Experience
- Vulnerability management: 5 years (Required)
- Penetration testing: 5 years (Required)
Location
Location: Singapore (Required)
Work Location: In person